Zero Day Monitor
ZDM
Dashboard
Vulnerabilities
Trending
Zero-Days
News
About
Login
CVE-2026-73343: WordPress WP Compress plugin < 7.20.01 - Remote Code Execution (RCE) vulnerability — Zero Day Monitor
← Back to list
10.0
CVE-2026-73343
KEV
EXPLOITED
PATCHED
aresit · wp compress
WordPress WP Compress plugin < 7.20.01 - Remote Code Execution (RCE) vulnerability
Description
Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions.
Affected Products
Vendor
Product
Versions
aresit
wp compress
n/a
References
https://patchstack.com/database/wordpress/plugin/wp-compress-image-optimizer/vulnerability/wordpress-wp-compress-plugin-7-20-01-remote-code-execution-rce-vulnerability?_s_id=cve
(vdb-entry)
Related News (1 articles)
Tier C
VulDB
5d ago
CVE-2026-73343 | AresIT Compress Plugin up to 7.20.0 on WordPress privileges management
→ No new info (linked only)
CVSS 3.1
10.0
CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CISA KEV
✅ Yes
Actively exploited
✅ Yes
Patch available
7.20.01
CWE
CWE-94
Published
Aug 18, 2026
Trending Score
51
Source articles
1
Independent
1
Info Completeness
0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack
Community Vote
0
Login to vote
0 upvotes
0 downvotes
No votes yet
Related CVEs (1)
MEDIUM
CVE-2026-17608
WP Compress <= 7.10.09 - Cross-Site Request Forgery to Arbitrary Options Deletion
Trending: 7
Pin to Dashboard
Verification
State:
unverified
Confidence:
0%
Vulnerability Timeline
CVE Published
Aug 18, 2026
Added to CISA KEV
Aug 18, 2026
Discovered by ZDM
Aug 18, 2026
Actively Exploited
Aug 18, 2026
Patch Available
Aug 18, 2026